Why zero trust fails on the plant floor — and what actually works in OT

IT-driven zero-trust frameworks break down in decentralized, high-pressure manufacturing environments. Here’s how to build security strategies that fit the realities of industrial operations.

Zero-trust insights

  • Zero trust fails in manufacturing because OT environments operate with different constraints, priorities and architectures than centralized IT systems.
  • Operational realities — such as downtime costs, incomplete asset inventories and legacy equipment — make traditional IT security controls impractical on the plant floor.
  • A practical OT cybersecurity strategy focuses on visibility, segmentation and access controls tailored to production needs, not strict adherence to IT frameworks.

IT teams are bringing zero-trust security frameworks to manufacturing plants. The problem is that IT looks at implementing zero trust from the lens of a centralized approach.

Industrial operational technology (OT) environments by their very nature are decentralized. Too many variables exist within an OT environment for a one-size-fits-all solution. A single pane of glass approach, while commendable, lacks a deeper understanding of how OT infrastructure is architected.

The strategy of forcing companies to conform a singular zero-trust approach into operational technology environments creates more problems than it solves.

The fundamental issue is that zero trust was designed for centralized and standardized information technology (IT) environments, where systems can be taken offline, patched regularly and controlled through centralized identity management.

Manufacturing plants don’t operate that way. No two plants are the same, even with the same company producing the goods.

Time is crucial in OT environments

When a machine center fails, every hour of downtime costs hundreds of thousands or even millions of dollars. Equipment vendors need immediate remote access to fix the problem. But if your security policies require a week of approvals before granting access, production teams will implement workarounds. Their revenue, safety and jobs depend on plant operation efficiencies.

Change management systems that work in IT don’t align with production needs. A maintenance window might reveal unexpected problems requiring immediate action across multiple systems. Production environments can’t wait for the trouble ticket process when production lines are down.

Asset inventories IT vs. OT

Zero trust requires knowing exactly what’s on your network. Most IT departments have solid asset inventories. Manufacturing plants don’t. The volume of assets in an OT versus IT environment is completely different. OT volumes are typically 20-25 assets for every IT asset.

Manufacturing plants run continuously. People constantly replace drives, HMIs, switches and sensors. Someone grabs parts from the storeroom, makes a repair and production continues. Without continuous monitoring that extends inside control panels, asset inventories can become outdated within weeks.

While modern tools can identify serial numbers, firmware versions and vulnerabilities remotely, most plants don’t realize this is possible. They assume the only way to get this information is through physical inspection during costly downtime.

Identity management gaps for zero trust

Zero trust relies on identity management. Every user needs unique credentials, multifactor authentication and role-based access. This works for IT systems, but it fails on plant floors.

Programmable logic controllers (PLCs) rarely support modern authentication methods. Most use shared passwords or default credentials. The same problem exists with Windows-based human-machine interfaces (HMIs). Operators share logins because the alternative is calling someone to reset a password while production sits idle.

These aren’t plant operators ignoring security. They’re employees who understand that if production stops, everyone’s job is at risk. Security measures that interfere with production won’t survive in manufacturing environments.

The network architecture challenge

IT environments are well defined with documented applications and network segmentation. Manufacturing plants are filled with different types of automation technologies, protocols and systems from multiple vendors that typically span decades.

Plants often have flat networks where everything can talk to everything. Some have super flat networks where sensors and drives sit on the same network as business systems with internet access.

The solution requires a bottom-up approach. Think of each facility as a bucket filled with equipment. You need to identify specific assets and move them into safer, segmented zones. This isn’t the top-down deployment that zero trust envisions. It’s tactical work done facility by facility. To be effective, you need to think globally but act locally.

Who should lead OT security efforts

Manufacturing is bottom line revenue generation. If production equipment isn’t operating making product, the company isn’t generating revenue. IT teams are tied to critical operations and try to impose security frameworks without understanding that production constraints will pose risk and failure.

IT security professionals who have been tasked with protecting manufacturing need to spend significant time in those environments. IT needs to be part of the plant operational OT ecosystem. At a minimum, they need an appreciation for how production teams operate, who their vendors are and their roles and what their actual constraints are.

Many IT teams simply don’t have the resources, plant operational knowledge or experience to do this effectively. That’s when organizations need to consider whether they should build new capabilities, reallocate resources or partner with outside OT experts.

Why buy-in is key for OT security

IT teams cannot effectively secure manufacturing operations alone. They need participation and buy-in from plant managers, engineering teams, OT system integrators, original equipment manufacturers (OEMs) and operations management. When operations teams recognize the value, they often will find a way to make budget available. Security can be included in capital equipment purchases rather than having to fight for separate funding.

The key is getting the right people in the room. When IT involves OT stakeholders (both internally and externally) and demonstrates understanding of operational constraints, the conversation changes.

Cybersecurity that actually works

Zero trust is a valuable long-term goal, but applying IT frameworks directly to manufacturing will not work effectively. Here’s what will:

  • Gain visibility into what’s actually in your environments: Use tools designed for OT that can identify assets without disrupting production.
  • Focus on segmentation: Isolate critical equipment from general plant networks and business systems for immediate security benefits without requiring full zero-trust architecture.
  • Implement appropriate access controls: This might not mean multifactor authentication on every device, but it does mean controlling and monitoring who has remote access and what they’re doing.

IT has been working on security for decades and still struggles with full implementation. Manufacturing environments are further behind and won’t catch up overnight. The goal is steady progress, not perfect implementation.

The bottom line is straightforward:

  • IT security professionals need to learn how manufacturing operates before trying to secure it.
  • Operations teams need to recognize that ignoring cybersecurity isn’t sustainable.
  • Organizations need to provide both groups with support and resources to work together effectively.

The threats facing manufacturing operations are real and growing, but the solution isn’t forcing IT security frameworks onto environments they weren’t designed for. It’s building security approaches that work within the constraints and realities of industrial operations.

AUTHOR

Dino Busalachi, Director BW Design Group, has close to four decades of global experience across IT, engineering and industrial control system (ICS) with multiple global brands. His knowledge and understanding of ICS, OT, IIoT and technology solutions allows him to provide expert insight and solutions for digital safety and cybersecurity in the industrial space.

LEARNING OBJECTIVES

  • Understand why traditional IT zero-trust frameworks fail when applied to decentralized, time-sensitive manufacturing environments.
  • Recognize the operational, architectural and identity-management constraints that require OT-specific cybersecurity approaches.
  • Identify practical strategies — such as asset visibility, segmentation and aligned access controls — that enable effective, realistic security in industrial operations.

CONSIDER THIS

How can your organization align its cybersecurity strategy with the operational realities of manufacturing instead of relying on IT frameworks that weren’t designed for OT environments?

Written by

Dino Busalachi

Dino Busalachi has more than three decades of global experience across information technology (IT), engineering and industrial control systems (ICS) with multiple globally recognized brands including Rockwell Automation, Anheuser Busch, American Standard, General Motors and more. Dino has deep knowledge and understanding of the inner workings of ICS, OT, IoT and technology solutions across almost every major vertical.